Privacy Policy
TeachersPlan ("we", "us") helps teachers create and organize classroom materials. This policy explains what the current product can collect, why it is used, and the choices you have. If anything is unclear, email [email protected]. School administrators may prefer our Trust Center, which covers our student-privacy posture and subprocessors in one place.
Student information — the short version
What we collect
- Account and profile data — email, optional display or school name, teaching state, class labels, grades, subjects, active-class settings, and other preferences you choose to save.
- Generated and saved materials — lessons, slides, worksheets, assessments, answer keys, source-based materials, and associated standards or topic context.
- Class-display data — content and labels you choose to present through a class display, along with the connection information needed to operate that feature.
- Collaboration content — teams, posts, direct messages, rooms, reactions, mentions, membership, and reports when you use Community features.
- Connected-service data — Google connection tokens and export history when you connect Google and request an export.
- Security and operational data — hashed sign-in codes and sessions, rate-limit records, request metadata, and moderation or abuse reports needed to operate and protect the service.
What is not required
- Student accounts, student rosters, grades tied to named students, IEP details, medical information, and discipline records are not required for the core creation workflow.
- Do not place that information in free-text fields. Technical controls cannot guarantee that a user will never type personal information into a prompt, saved document, display, or message.
- TeachersPlan does not use account content to build advertising profiles or sell it to advertisers.
How sign-in works
We use passwordless email sign-in. When you log in we send a 6-digit code to your email; the code is stored only as a one-way hash, expires after 15 minutes, and is single-use. Sign-in tokens are scoped to your account.
Your generated materials
Materials saved to your Library are tied to your account. Content remains private unless you deliberately place it in a sharing, Community, messaging, team, or class-display feature. Deleting a Library item removes that saved item; copies you exported or shared outside TeachersPlan are controlled by their destination.
Teacher-provided sources
A PDF selected in the app is read in your browser and the original file is not uploaded by that PDF reader. The text extracted from the PDF is sent to TeachersPlan and a configured AI provider when you ask the service to generate materials from it. Pasted text, fetched web text, video context, topics, and instructions are also transmitted as needed for the requested generation. Do not use student work or confidential records as a source.
How your data is encrypted
TeachersPlan uses HTTPS/TLS for network traffic. Google connection tokens are encrypted by the application using AES-GCM before storage when that integration is configured. Cloudflare provides the hosting, Worker, and D1 security controls described in its own service documentation. These vendor controls are not a TeachersPlan security certification.
AI generation
Generation requests may include state, grade, subject, the selected standards record, custom topic, teacher instructions, and teacher-provided source text. Some document workflows may also include a teacher or school name when you ask to place it in the document. Requests are sent to the AI provider configured for the service, which may include Anthropic, a configured OpenAI-compatible provider, or Cloudflare Workers AI. Production provider and contract terms must be verified operationally; do not rely on an unsupported promise about provider retention or model training. TeachersPlan does not operate an advertising model and does not intentionally use your account content to train a model of its own.
Student privacy posture
The product is designed so teachers can create ordinary materials without student records or student accounts. Optional roster names used for per-student printing are stored locally in the browser. Class labels, saved materials, displays, and shared free text can be stored on the service, so users must not place student personal information in them. Whether and how education privacy laws apply is a determination for the school, district, and its advisers; TeachersPlan does not claim automatic compliance or approval.
Subprocessors
The source code supports the following provider categories. The exact deployed list and contractual terms should be confirmed with [email protected] during an evaluation:
- Cloudflare — hosting, Worker execution, D1 database, and optional fallback generation through Workers AI.
- Configured AI provider — Anthropic, an OpenAI-compatible endpoint, or Cloudflare Workers AI may receive the lesson context, instructions, and source text required to perform generation.
- Google (Drive export) — optional export to Google Drive / Docs / Slides, only when you
connect Google and choose to export. We request the
drive.filescope — per-file access to files you create with TeachersPlan, not your whole Drive. - Transactional email provider — delivers one-time sign-in codes and other emails you explicitly request. The deployed provider must be confirmed operationally.
District & school use
Google export requests the drive.file scope. District approval, purchasing terms, and the
availability and contents of any Data Processing Agreement must be confirmed before institutional use.
Your data, your control — export & deletion
The account drawer provides self-service export and deletion controls:
- Export — download the account categories included by the export endpoint. Operational security records and copies held by external export destinations may not be included.
- Delete — request removal of account-linked TeachersPlan data from the Account drawer. The service must report an error rather than claim success if any required deletion operation fails.
Prefer email? You can also reach us at [email protected] from your account email, or contact [email protected] for security and administrator questions. Ask whether a current Data Processing Agreement is available; do not assume one exists until it is provided and executed.
Changes
If we update this policy we'll change the date above and, for material changes, notify you by email.